Sample questions
Microsoft Security Operations Analyst SC-200 practice questions
Your organization uses Microsoft 365 Defender. An incident is created for a user who received a phishing email that contained a link to a malicious website. The user clicked the li…
A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect a possible password spray attack. The rule must trigger when a single source IP address has mor…
Which THREE are valid incident classification options in Microsoft Sentinel?
Your organization uses Microsoft Sentinel to manage security incidents. The security team wants to automatically close low-severity incidents after 24 hours if no activity has occu…
You are a security operations analyst at a company that uses Microsoft Sentinel. You need to create an automation rule that automatically closes incidents with a severity of Inform…
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →Your organization uses Microsoft Sentinel and has enabled UEBA. You notice that many low-severity incidents are being created from high-volume informational alerts. You want to red…
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →A SOC team wants to use Microsoft Sentinel to detect when a user logs in from a new country not previously seen for that user. They have the SigninLogs table. Which KQL function is…
Wide World Importers uses Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Purview for data loss prevention (DLP). An incident is generated: 'DLP policy violation - sensit…
Your organization uses Microsoft Defender XDR for threat detection and response. The security team wants to automatically isolate a compromised device when a specific malware alert…
A security analyst receives a high-severity incident in Microsoft Sentinel for a user who is suspected of lateral movement. The analyst wants to automatically run a playbook that i…
Your organization uses Microsoft Defender XDR. You need to investigate a potential ransomware incident that has affected multiple devices. The security team wants to identify the i…
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →During a ransomware incident, Microsoft Defender for Cloud Apps alerts indicate that a user is uploading large volumes of data to an external cloud storage provider not approved by…
Which THREE components are part of Microsoft Defender XDR? (Select three.)
Your organization, Fabrikam, has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You are using Microsoft Sentinel and Microsoft Defender XDR. You hav…
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →During a threat hunt, you want to identify processes that have made network connections to known malicious IP addresses. Which data source in Microsoft Defender for Endpoint would…
You are investigating an incident where a user reported receiving a suspicious email with a malicious attachment. Microsoft Defender for Office 365 did not block it. The email orig…
During a threat hunt in Microsoft Sentinel, you find a series of suspicious sign-ins to Microsoft Entra ID from an IP address known to be associated with a threat actor. Which enti…
Your organization has a hybrid identity environment with Microsoft Entra ID and on-premises Active Directory. You suspect a compromised on-premises admin account that has been used…
A security analyst in Microsoft Defender for Cloud receives an alert that an Azure VM has a vulnerability with a high severity. The analyst wants to see the detailed finding, inclu…
As a threat hunter at Contoso, you are investigating a potential advanced persistent threat (APT) that may have compromised multiple Azure subscriptions. You have Microsoft Defende…
A threat hunter runs the KQL query above in Microsoft Sentinel. What is the main limitation of this query?
You are using Microsoft Sentinel to manage incidents. You want to automatically close incidents that are older than 90 days and have a status of 'New'. What is the most efficient w…
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)
Which TWO conditions must be met to enable Microsoft Sentinel UEBA? (Choose two.)
Manage a security operations environmentmediumSee the answer and why each option is right or wrong →